RRAMC — Resistive random access memory controller

The resistive random access memory controller (RRAMC) is used for writing the internal RRAM memory, the secure information configuration region (SICR), and the user information configuration registers (UICR).

The main features of RRAMC are:

Reading from RRAM

RRAM can be read using any natural alignment.

Read and execute operations are cachable through CACHE — Instruction/data cache. For execution performance figures, see CPU.

Low latency mode

The low power register allows making trade-offs between latency and power consumption. By default, RRAMC goes into PowerDown mode, so the wakeup time is variable. To enable a sleep mode with faster wake-up, configure Standby mode using register POWER.LOWPOWERCONFIG.MODE. In combination with Constant Latency sub-power mode, this ensures the lowest latency.

Writing to RRAM

When writing is enabled in register CONFIG.WEN, and CONFIG.WRITEBUFSIZE is set to Unbuffered, RRAM is written using any natural alignment (byte, half-word, 32-bit, or 64-bit).

RRAMC always writes full wordlines. When data is written to RRAM, the entire wordline is written and ECC is updated, even if only a single bit is changed. This has an effect on the endurance of the RRAM, as each write operation counts as a write to all bits in the wordline.

RRAMC is able to write both 0 and 1 to any bit in RRAM, even if that bit has been written before.

When writing with CONFIG.WRITEBUFSIZE set to Unbuffered, the written data (byte, half-word, 32-bit, or 64-bit) is committed to RRAM immediately.

Buffered RRAM write

RRAMC enables fast buffered writes for contiguous memory regions.

RRAMC has an internal write-buffer that can be configured using CONFIG.WRITEBUFSIZE.

When buffered writes are enabled, RRAMC will collect as much data as possible in the internal write-buffer, before bulk-committing the buffer to RRAM.

When committing to RRAM, the commit operation updates only the data in RRAM memory that has modified values. Values that have not been altered remain unchanged in RRAM.

To use buffered writes, perform the following operations:
  1. Enable writing using CONFIG.WEN, and configure CONFIG.WRITEBUFSIZE.
  2. Write to RRAM memory in incrementing address order.
RRAMC commits the write-buffer when either of the following occurs:
  • The write-buffer is full
  • The address written is outside the buffer area
  • There is a read operation from a 64-bit word line in the buffer that has already been written to
RRAMC stalls while the commit takes place, and additional wait-states can be observed for the bus access.
In addition to the automatic commit, a commit can also be triggered by the following:

The manual triggers are useful in situations where it is crucial to ensure that the write buffer has been committed. Register BUFSTATUS.WRITEBUFEMPTY can be used to check if the write-buffer is empty, or if it contains uncommitted data.

Note: The internal write-buffer is volatile, and data loss may occur during a power failure or when entering System OFF mode with uncommitted data in the buffer. Having uncommitted data in the internal write-buffer will keep the RRAM active, and thus increase power consumption during sleep mode.

Erasing RRAM

RRAMC provides a mechanism to erase the whole RRAM in one operation by using the ERASE.ERASEALL register.

When ERASEALL is triggered, RRAMC will write 0xFFFFFFFF to the entire RRAM memory, including user information configuration registers (UICR) and the secure information configuration region (SICR) . ERASEALL will not erase the factory information configuration registers (FICR).

This functionality can be blocked by ERASE protection. For details, see CTRL-AP — Control access port.

Note: Unlike the CTRL-AP ERASEALL operation that can be activated from a debugger, the RRAMC ERASEALL operation will not automatically grant access to the debug access port.
Note: The write-buffer must be committed before initiating an erase operation.

Region protection

The RRAM memory can be divided into several regions and these regions can be configured to restrict accesses.

Each region is configured using the REGION[n].ADDRESS and REGION[n].CONFIG registers.

When the region write-once feature is enabled, writes to a 32-bit words in the region are allowed only when the current data is 0xFFFFFFFF, else the writes are ignored.

When the region configuration registers are writable, the region configuration registers can be updated until the lock bit is set to Enabled. However, the register fields Secure, Read, Write, amd Execute can be written to 0, even if the lock bit is set to Enabled.

After changing the region protecton, CACHE must be invalidated to stay coherent with the updated RRAM configuration. Failure to do so will cause unpredictable results, such as being able to read cached content from a memory region that was just configured to be non-readable.

Note: The configuration registers for some of the regions are read-only and are reserved by the system configurations. See the register configuration table below for regions available for users.

Immutable boot region

RRAMC can make a part of the RRAM code memory immutable.

The immutable boot region has configurable permissions settings. Read, write, and execute permissions are configured individually. By making the region read-execute only, that memory range of the RRAM becomes immutable.

The region starts at address 0x00000000 and the size of the region is configurable. Note that the region does not add additional storage, but enforces permission settings on the memory range.

The size and permission settings of the immutable boot region is configured in UICR. If UICR.BOOTCONF is not configured, RRAMC will not enforce the protection.

Once the boot region protection is enabled, it can only be removed by ERASEALL. Erase protection can be enabled to prevent ERASEALL operation. For more information about erase protection, see CTRL-AP — Control access port.

Power-failure protection

Power failure protection is possible by using the power-fail comparator (POF) that is monitoring power supply.

If the power-fail comparator is enabled, and the power supply voltage is below the POF threshold, the power-fail comparator will prevent RRAMC from performing write operations. For more information about POF, see Power-fail comparator.

If a power failure warning is present at the start of an RRAM write operation, RRAMC will block the operation and a bus error will be signaled.

If a power failure warning occurs during an ongoing RRAM write, RRAMC can be configured to handle this in two ways:
  • If POWER.CONFIG.POF = Abort, then RRAMC will stop the commit process from the internal write-buffer as soon as the condition occurs. After a power-failure event, the write buffer must be cleared by using the CLRWRITEBUF task before writing more data to RRAM.
  • If POWER.CONFIG.POF = Wait, then RRAMC will try to complete the on-going write despite the warning of the operating voltage becoming too low.

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA
RRAMCGLOBAL0x5004E000HFSNANo

RRAM Non-Volatile Memory Controller

Configuration

InstanceDomainConfiguration
RRAMCGLOBAL

RRAM word size : 128 bits per wordline

Maximum write buffer size : 16

Register overview

RegisterOffsetTZDescription
TASKS_WAKEUP0x000

Wakeup the RRAM from low power mode

TASKS_CLRWRITEBUF0x004

Clear internal write-buffer

TASKS_COMMITWRITEBUF0x008

Commits the data stored in internal write-buffer to RRAM

SUBSCRIBE_WAKEUP0x080

Subscribe configuration for task WAKEUP

SUBSCRIBE_CLRWRITEBUF0x084

Subscribe configuration for task CLRWRITEBUF

SUBSCRIBE_COMMITWRITEBUF0x088

Subscribe configuration for task COMMITWRITEBUF

EVENTS_WOKENUP0x100

RRAMC is woken up from low power mode

EVENTS_READY0x104

RRAMC is ready

EVENTS_READYNEXT0x108

Ready to accept a new write operation

EVENTS_ACCESSERROR0x10C

RRAM access error

PUBLISH_WOKENUP0x180

Publish configuration for event WOKENUP

INTEN0x300

Enable or disable interrupt

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

INTPEND0x30C

Pending interrupts

READY0x400

RRAMC ready status

READYNEXT0x404

Ready next flag

ACCESSERRORADDR0x408

Address of the first access error

BUFSTATUS.WRITEBUFEMPTY0x418

Internal write-buffer is empty

ECC.ERRORADDR0x420

Address of the first ECC error that could not be corrected

CONFIG0x500

Configuration register

READYNEXTTIMEOUT0x50C

Configuration for ready next timeout counter, in units of AXI clock frequency

POWER.CONFIG0x510

Power configuration

POWER.LOWPOWERCONFIG0x518

Low power mode configuration

ERASE.ERASEALL0x540

Erase RRAM, including UICR

All information in SICR, including keys, are also erased

REGION[n].ADDRESS0x550

Region address

REGION[n].CONFIG0x554

Region configuration

TASKS_WAKEUP

Address offset: 0x000

Wakeup the RRAM from low power mode

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_WAKEUP

Wakeup the RRAM from low power mode

Trigger

1

Trigger task

TASKS_CLRWRITEBUF

Address offset: 0x004

Clear internal write-buffer

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_CLRWRITEBUF

Clear internal write-buffer

Trigger

1

Trigger task

TASKS_COMMITWRITEBUF

Address offset: 0x008

Commits the data stored in internal write-buffer to RRAM

READY status is updated during this operation

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_COMMITWRITEBUF

Commits the data stored in internal write-buffer to RRAM

READY status is updated during this operation

Trigger

1

Trigger task

SUBSCRIBE_WAKEUP

Address offset: 0x080

Subscribe configuration for task WAKEUP

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task WAKEUP will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_CLRWRITEBUF

Address offset: 0x084

Subscribe configuration for task CLRWRITEBUF

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task CLRWRITEBUF will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_COMMITWRITEBUF

Address offset: 0x088

Subscribe configuration for task COMMITWRITEBUF

READY status is updated during this operation

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task COMMITWRITEBUF will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

EVENTS_WOKENUP

Address offset: 0x100

RRAMC is woken up from low power mode

This event is triggered only if waken up by the WAKEUP task

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_WOKENUP

RRAMC is woken up from low power mode

This event is triggered only if waken up by the WAKEUP task

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_READY

Address offset: 0x104

RRAMC is ready

This event is also generated when the CPU is waking up from sleep

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_READY

RRAMC is ready

This event is also generated when the CPU is waking up from sleep

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_READYNEXT

Address offset: 0x108

Ready to accept a new write operation

This event is also generated when the CPU is waking up from sleep

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_READYNEXT

Ready to accept a new write operation

This event is also generated when the CPU is waking up from sleep

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_ACCESSERROR

Address offset: 0x10C

RRAM access error

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_ACCESSERROR

RRAM access error

NotGenerated

0

Event not generated

Generated

1

Event generated

PUBLISH_WOKENUP

Address offset: 0x180

Publish configuration for event WOKENUP

This event is triggered only if waken up by the WAKEUP task

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event WOKENUP will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

INTEN

Address offset: 0x300

Enable or disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

WOKENUP

Enable or disable interrupt for event WOKENUP

This event is triggered only if waken up by the WAKEUP task

Disabled

0

Disable

Enabled

1

Enable

B

RW

READY

Enable or disable interrupt for event READY

This event is also generated when the CPU is waking up from sleep

Disabled

0

Disable

Enabled

1

Enable

C

RW

READYNEXT

Enable or disable interrupt for event READYNEXT

This event is also generated when the CPU is waking up from sleep

Disabled

0

Disable

Enabled

1

Enable

D

RW

ACCESSERROR

Enable or disable interrupt for event ACCESSERROR

Disabled

0

Disable

Enabled

1

Enable

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

WOKENUP

Write '1' to enable interrupt for event WOKENUP

This event is triggered only if waken up by the WAKEUP task

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1S

READY

Write '1' to enable interrupt for event READY

This event is also generated when the CPU is waking up from sleep

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

C

RW
W1S

READYNEXT

Write '1' to enable interrupt for event READYNEXT

This event is also generated when the CPU is waking up from sleep

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

D

RW
W1S

ACCESSERROR

Write '1' to enable interrupt for event ACCESSERROR

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

WOKENUP

Write '1' to disable interrupt for event WOKENUP

This event is triggered only if waken up by the WAKEUP task

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1C

READY

Write '1' to disable interrupt for event READY

This event is also generated when the CPU is waking up from sleep

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

C

RW
W1C

READYNEXT

Write '1' to disable interrupt for event READYNEXT

This event is also generated when the CPU is waking up from sleep

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

D

RW
W1C

ACCESSERROR

Write '1' to disable interrupt for event ACCESSERROR

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTPEND

Address offset: 0x30C

Pending interrupts

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

WOKENUP

Read pending status of interrupt for event WOKENUP

This event is triggered only if waken up by the WAKEUP task

NotPending

0

Read: Not pending

Pending

1

Read: Pending

B

R

READY

Read pending status of interrupt for event READY

This event is also generated when the CPU is waking up from sleep

NotPending

0

Read: Not pending

Pending

1

Read: Pending

C

R

READYNEXT

Read pending status of interrupt for event READYNEXT

This event is also generated when the CPU is waking up from sleep

NotPending

0

Read: Not pending

Pending

1

Read: Pending

D

R

ACCESSERROR

Read pending status of interrupt for event ACCESSERROR

NotPending

0

Read: Not pending

Pending

1

Read: Pending

READY

Address offset: 0x400

RRAMC ready status

The event READY is generated when the status changes to Ready

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

READY

RRAMC is ready or busy

The status is updated for all RRAMC operations except during read and writes to write-buffer

Busy

0

RRAMC is busy

Ready

1

The current RRAMC operation is completed and RRAMC is ready

READYNEXT

Address offset: 0x404

Ready next flag

The event READYNEXT is generated when the READYNEXT status changes to Ready

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

READYNEXT

RRAMC can accept a new write operation

Busy

0

RRAMC cannot accept any write operation now

Ready

1

RRAMC is ready to accept a new write operation

ACCESSERRORADDR

Address offset: 0x408

Address of the first access error

The event ACCESSERROR is generated on access error. When this event is cleared, this register is updated on the next access error

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x00FFFFFF00000000111111111111111111111111
IDR/WFieldValue IDValueDescription
A

R

ADDRESS

Access error address

The most significant 8 bits are set to zero always

BUFSTATUS.WRITEBUFEMPTY

Address offset: 0x418

Internal write-buffer is empty

The internal write-buffer has been committed to RRAM and is now empty

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

EMPTY

NotEmpty

0

The internal write-buffer has data that needs committing

Empty

1

The internal write-buffer is empty and has no content that needs to be committed

ECC.ERRORADDR

Address offset: 0x420

Address of the first ECC error that could not be corrected

The event ECCERROR is generated on ECC error. When this event is cleared, this register is updated on the next ECC error

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x00FFFFFF00000000111111111111111111111111
IDR/WFieldValue IDValueDescription
A

R

ADDRESS

ECC error address

The most significant 8 bits are set to zero always

CONFIG

Address offset: 0x500

Configuration register

Bit number313029282726252423222120191817161514131211109876543210
IDBBBBBBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

WEN

Write enable

Disabled

0

Write is disabled

Enabled

1

Write is enabled

B

RW

WRITEBUFSIZE

0..16

write-buffer size in number of 128-bit words

Unbuffered

0

Disable buffering

READYNEXTTIMEOUT

Address offset: 0x50C

Configuration for ready next timeout counter, in units of AXI clock frequency

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAAAAAA
Reset 0x0000008000000000000000000000000010000000
IDR/WFieldValue IDValueDescription
A

RW

VALUE

[0..4095]

Preload value for waiting for a next write

B

RW

EN

Enable ready next timeout

The timeout value is number of RRAMC clock cycles. The timeout starts when the READYNEXT is set to ready

Disable

0

Disable ready next timeout

Enable

1

Enable ready next timeout

POWER.CONFIG

Address offset: 0x510

Power configuration

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAAAAAAAAAA
Reset 0x0000010000000000000000000000000100000000
IDR/WFieldValue IDValueDescription
A

RW

ACCESSTIMEOUT

Access timeout, in 31.25 ns units, used for going into standby power mode or remain active on wake up

The timeout counter counts down and is restarted on every RRAM access and on event WOKENUP

B

RW

POF

Power on failure warning handling configuration

Wait

0

Wait until the current RRAM write finishes

Abort

1

Abort the current RRAM write

POWER.LOWPOWERCONFIG

Address offset: 0x518

Low power mode configuration

The RRAMC low power mode is entered while the device goes into system on idle

Bit number313029282726252423222120191817161514131211109876543210
IDAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

MODE

RRAM low power mode

PowerDown

0

The RRAM goes into power down mode

Standby

1

The RRAM automatically goes into standby mode while the RRAM is not being accessed

This mode gives faster wake-ups, and is useful in combination with Constant Latency sub-power mode.

NAP

2

The RRAM goes into NAP mode

PowerOff

3

The RRAM is powered Off

ERASE.ERASEALL

Address offset: 0x540

Erase RRAM, including UICR

All information in SICR, including keys, are also erased

The status in READY is updated during this operation

Writes to this register are ignored when erase protect is enabled

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

ERASE

Erase RRAM

NoOperation

0

No operation

Erase

1

Start erase of chip

REGION[n]

RRAMC can apply access privileges to regions of the RRAM. Some regions are dedicated for system use and are not available for configuration - refer to the instantiation table for details.

REGION[n].ADDRESS

Address offset: 0x550 + (n × 0x8)

Region address

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

STARTADDR

Start address of the region [n]

Bits [31:24] and bit [9:0] are read-only and set to zero

REGION[n].CONFIG

Address offset: 0x554 + (n × 0x8)

Region configuration

The register fields READ, WRITE and EXECUTE can can be written to 0, even when the LOCK field is set to Enabled.

Bit number313029282726252423222120191817161514131211109876543210
IDHHHHHHHGFEEEEDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

READ

Read access

NotAllowed

0

Read access to override region [n] is not allowed

Allowed

1

Read access to override region [n] is allowed

B

RW

WRITE

Write access

NotAllowed

0

Write access to override region [n] is not allowed

Allowed

1

Write access to override region [n] is allowed

C

RW

EXECUTE

Execute access

NotAllowed

0

Execute access to override region [n] is not allowed

Allowed

1

Execute access to override region [n] is allowed

D

RW

SECURE

Secure access

NonSecure

0

Both Secure and non-Secure access to override region [n] is allowed

Secure

1

Only secure access to override region [n] is allowed

E

RW

OWNER

Owner ID

NotEnforced

0

Owner ID protection is not enforced

F

RW

WRITEONCE

Write-once

Disabled

0

Write-once disabled

Enabled

1

Write-once enabled

G

RW
W1S

LOCK

Enable lock

Disabled

0

Lock disabled for region [n]

Enabled

1

Lock enabled for region [n]

H

RW

SIZE

Size in KBytes of region [n]